WordPress Plugin Security Update Advisory (CVE-2025-22777)

Overview

We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.

 

Affected Products

CVE-2025-22777

WordPress GiveWP Plugin Version: ~ 3.19.3 (inclusive)

 

Resolved Vulnerabilities

Data deserialization vulnerability allowing PHP object injection (CVE-2025-22777)

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2025-22777

WordPress GiveWP Plugin Version: 3.19.4

 

 

Referenced Sites

[1] WordPress GiveWP Plugin <= 3.19.3 is vulnerable to PHP Object Injection
https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-3-19-3-php-object-injection-vulnerability?_s_id=cve